GitLab fixed a serious vulnerability, users should upgrade in a timely manner
According to Slow Fog monitoring, GitLab CE/EE has a serious path traversal vulnerability CVE-2026-85706, with a CVSS score of 10. An unauthenticated attacker can read any file on the affected GitLab server through the Repository Commits API. GitLab has released a security patch.Affected versions include those from 18.7 up to but not including 19.1.8, from 19.2 up to but not including 19.2.6, and from 19.3 up to but not including 19.3.2. Self-managed GitLab users should upgrade immediately to 19.1.8, 19.2.6, or 19.3.2, and check logs and potentially exposed credentials after patching.